hermes-studio-dashboard
Warn
Audited by Snyk on Jun 14, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.75). Hermes Studio’s runtime chat flow ingests user-supplied
message/roommessagefields (e.g., via Socket.IOchat-run/group-chat-messageor REST/api/hermes/chat) into the agent context; if those messages originate from outsiders (e.g., Telegram/Discord/Slack users), they become free text in the LLM prompt.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata